PT-2025-17726 · Apache+2 · Apache Httpclient+3

Joe Gallo

·

Published

2025-03-06

·

Updated

2025-08-07

·

CVE-2025-27820

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache HttpClient versions 5.4.0 through 5.4.2
Description A bug in PSL validation logic disables domain checks, affecting cookie management and host name verification. This issue was discovered by the Apache HttpClient team.
Recommendations For Apache HttpClient versions 5.4.0 through 5.4.2, update to version 5.4.3 to resolve the issue. As a temporary workaround, consider restricting cookie management and host name verification until the update is applied.

Fix

LPE

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2025-9506
ALT-PU-2025-9551
BDU:2025-05017
CVE-2025-27820
GHSA-73M2-QFQ3-56CX

Affected Products

Alt Linux
Apache Httpclient
Bamboo
Confluence